jfrog

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The install path for the Membrane CLI appears legitimate and official, but the skill's actual footprint routes JFrog authentication and API traffic through Membrane instead of the official JFrog API directly. That third-party credential handling and proxying are inconsistent enough with a plain JFrog integration to raise medium risk, though there is no clear evidence of outright malware or obfuscation.

Confidence: 89%Severity: 64%
Audit Metadata
Analyzed At
Apr 22, 2026, 01:58 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fjfrog%2F@54ac42e5660930e5151356ea938222b6872d432b